BluePass: A Mobile Device Assisted Password Manager

Authors

  • Yue Li William & Mary image/svg+xml
  • Haining Wang University of Delaware
  • Kun Sun George Mason University

DOI:

https://doi.org/10.4108/eai.10-1-2019.156244

Keywords:

Authentication, Password, Password Manager, Two-factor Authentication

Abstract

With the growing number of online accounts a user possesses, managing passwords has been unprecedentedly challenging. Password managers have emerged to help users managing their passwords. However, state-of-the-art cloud based password managers are vulnerable to data breach and a master password becomes a single point of failure. To address these security vulnerabilities, we propose BluePass, a password manager that stores the password vault (i.e., the set of all the encrypted site passwords of a user) locally in a mobile device and a decryption key to the vault in the user computer. BluePass partially inherits the security characteristics of two-factor authentication by requiring both a mobile device and a master password to retrieve and decrypt the site passwords. BluePass leverages short-range nature of Bluetooth to automatically retrieve site passwords and fill the login fields, providing a hand-free user experience.

Downloads

Published

21-12-2018

How to Cite

1.
Li Y, Wang H, Sun K. BluePass: A Mobile Device Assisted Password Manager. EAI Endorsed Trans Sec Saf [Internet]. 2018 Dec. 21 [cited 2025 Nov. 22];5(17):e3. Available from: https://publications.eai.eu/index.php/sesa/article/view/193

Most read articles by the same author(s)